Balancer Composable Stable Pools Exploited Across Six Chains on Nov. 4

Balancer V2's Composable Stable Pools were exploited on Nov. 4 across Ethereum, Base, Avalanche, Polygon, Arbitrum, and other chains due to a rounding logic flaw in batchSwap EXACT_OUT transactions, an official incident report released Nov. 6 shows. The vulnerability allowed attackers to manipulate pool balances and extract assets, while Balancer V3 and other pool types remained unaffected. The team, working with security partners and white hat groups, contained the exploit through Hypernative's automatic pause, asset freezes, and SEAL framework interventions. StakeWise recovered approximately 73.5% of stolen osETH, with BitFinding and Base MEV bot teams assisting in partial fund recovery.